Courseiva

CRISC Information Technology and Security Practice Question

A power utility is required to comply with NERC CIP standards. Which of the following is a primary objective of these standards?

⚠ Common exam trap

CRISC often tests the distinction between IT and OT security objectives; candidates may confuse interoperability or protocol standardization with the core reliability mission of NERC CIP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Protect the reliability of the bulk electric system

NERC CIP (Critical Infrastructure Protection) standards are mandatory reliability standards specifically designed to protect the bulk electric system (BES) from cyber and physical threats. Their primary objective is to ensure the reliable operation of the BES by securing the assets that control and monitor it. This is a regulatory requirement for power utilities in North America.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Standardize industrial control protocols

    Why it's wrong here

    NERC CIP mandates security controls for critical cyber assets; it does not prescribe or standardise industrial control protocols such as DNP3 or Modbus, which are set by standards bodies and vendors. It is tempting because protocol uniformity aids security, but the standards address protection of assets, not protocol harmonisation.

  • ✗

    Reduce energy consumption

    Why it's wrong here

    NERC CIP exists to protect the bulk electric system's cyber assets, not to curb consumption; energy reduction is an efficiency or sustainability goal, not a reliability-security mandate. It is tempting because utilities do pursue demand reduction, but that falls under other regulatory drivers, not the critical infrastructure protection standards.

  • ✗

    Ensure interoperability between IT and OT systems

    Why it's wrong here

    NERC CIP's objective is securing bulk electric system cyber assets, not engineering IT/OT interoperability, which is a convergence or architecture concern. It is tempting because CIP compliance touches both IT and OT environments, but interoperability is a design goal, not the standards' stated purpose of protecting reliability.

  • ✓

    Protect the reliability of the bulk electric system

    Why this is correct

    NERC CIP standards mandate controls such as electronic security perimeters, access management and incident reporting for entities operating bulk electric system assets. Their primary objective is protecting the reliability of that system, satisfying the stem's compliance requirement for the power utility.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.